A DoS/DDoS Attack Detection System Using Chi-Square Statistic Approach
Fang-Yie Leu, I-Long Lin
Nowadays, users can easily access and download network attack
tools, which often provide friendly interfaces and easily operated
features, from the Internet. Therefore, even a naive hacker can
also launch a large scale DoS or DDoS attack to prevent a system,
i.e., the victim, from providing Internet services. In this paper, we
propose an agent based intrusion detection architecture, which is a
distributed detection system, to detect DoS/DDoS attacks by
invoking a statistic approach that compares source IP addresses’
normal and current packet statistics to discriminate whether there
is a DoS/DDoS attack. It first collects all resource IPs’ packet
statistics so as to create their normal packet distribution. Once
some IPs’ current packet distribution suddenly changes, very
often it is an attack. Experimental results show that this approach
can effectively detect DoS/DDoS attacks. Full Text
|